Configuring SAP GRC Click the Patches Updates tab.

27-12 Oracle Fusion Middleware Developers Guide for Oracle Identity Manager 5. Run the following command to import the GRC certificate to cacerts: keytool -import -alias sapgrc_trusted_cert -file JAVA_HOMElibsecurityCERTIFICATE_FILENAME -trustcacerts -keystore JAVA_HOMElibsecuritycacerts -storepass changeit In this command: – CERTIFICATE_FILENAME is the name of certificate that has been exported from the SAP GRC host computer – The -storepass changeit clause specifies the password for the cacerts keystore. 6. When prompted to specify whether or not you want to trust the certificate, enter yes . The Certificate was added to keystore message is displayed.

27.7.3 Calling SoD Check Web Service Over SSL

SOA calls the Oracle Identity Manager Web service over the URL given as the oimFrontEndURL , which is the URL used to access the Oracle Identity Manager UI, in the oim-config.xml file. By default, this is a HTTP URL. You can change this to HTTPS so that communication takes place over SSL. The SSL port for Oracle Identity Manager can be viewed on the WebLogic Administrative Console. To call SoD check Web service over SSL: 1. Locate the Oracle Identity Manager SSL port. To do so: a. Login to the WebLogic Administrative Console.

b. Go to servers, oim_server1. You can see that SSL Listen Port is enabled.

2. Change the oimFrontEndURL through the MBeans browser in Enterprise Manager. To do so: a. Login to Enterprise Manager.

b. Go to oim_server1.

c. From the list on the top of the page, select System Mbeans Browser.

d. Go to Application Defined Mbeans, oracle.iam, Server: oim_server1,

Application: oim , XMLConfig, Config, XMLConfig.DiscoveryConfig, and Discovery . The attributes are displayed to the right.

e. Click oimFrontEndURL, and change its value, as shown:

https:HOST_NAME:SSL_PORT

3. Restart Oracle Identity Manager.

4. Create a request for SoD-enabled resource. You can view the new workflow

instance in Enterprise Manager. The Web service will be called on SSL port. Note: The value of oimFrontEndURL can also be set at the time of installing Oracle Identity Manager. Using Segregation of Duties SoD 27-13

27.8 Configuring Workflows on Non SoD-enabled Connectors

Perform the procedures described in this section only if you are not using one of the preconfigured SoD-compatible connectors Oracle e-Business User Management, SAP User Management, and SAP CUA. This section discusses the following procedures: ■ Modifying the Approval Workflow for SoD ■ Modifying the Provisioning Workflow for SoD

27.8.1 Modifying the Approval Workflow for SoD

To modify the approval workflow for SoD validation:

1. Instead of object forms in earlier releases of Oracle Identity Manager, the data to

be entered while creating a request in 11g Release 1 11.1.1 is entered in request datasets. If the request datasets are not already present for the target system resource to be provisioned, then create new parent and child datasets and import them to MDS by using the MDS Import Utility. Note: It is assumed that Oracle Identity Manager and SOA are running on the same Java Runtime Environment JRE. If SOA and Oracle Identity Manager are running on different JREs, then WebLogic certificate exchange is required for SSL communication. For details, see Oracle WebLogic Server 10g Release 3 10.3 documentation in the Oracle Technology Network OTN Web site by using the following URL: http:www.oracle.comtechnetworkmiddlewareweblogi cdocumentationindex.html